I cannot post the DDS log because the GMER scan will not complete. The first time I ran it I received a message indicating that "symantic service framework has stopped working. Windows will close program and notify you if solution is available." The next time I ran the scan I received a message that "windows has recovered from an unexpected shutdown" and a message that said "host process for windows service has stopped working and closed".
Thanks in advance for any help that you can provide! Much appreciated!
NOTE: I tried running TDS killer but it found nothing and didn't help either.
I am running Windows Vista Home Premium and I believe it is 32 bits.
-Shiba
Edit: I tried doing the GMER scan again last night and it never seems to get to the screen that I see in the directions thread. See below for what it looks like when I clicked save in the morning after running the scan last night.
MER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-08-15 07:30:00
Windows 6.0.6001 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD32 rev.11.0
Running: gmer.exe; Driver: C:\Users\Jared\AppData\Local\Temp\awdoypow.sys
---- System - GMER 1.0.15 ----
SSDT 90790938 ZwAlertResumeThread
SSDT 907546B0 ZwAlertThread
SSDT 9075A500 ZwAllocateVirtualMemory
SSDT 8F7524F0 ZwAlpcConnectPort
SSDT 907930A8 ZwCreateMutant
SSDT 9075A590 ZwCreateThread
SSDT 9075BB90 ZwDebugActiveProcess
SSDT 9076ABD0 ZwFreeVirtualMemory
SSDT 90793178 ZwImpersonateAnonymousToken
SSDT 90793238 ZwImpersonateThread
SSDT 90760A40 ZwMapViewOfSection
SSDT 90768B88 ZwOpenEvent
SSDT 9075A388 ZwOpenProcessToken
SSDT 90768A08 ZwOpenSection
SSDT 90766EF0 ZwOpenThreadToken
SSDT 90771E10 ZwResumeThread
SSDT 9075FC00 ZwSetContextThread
SSDT 90766FC0 ZwSetInformationProcess
SSDT 90766D98 ZwSetInformationThread
SSDT 90768AC8 ZwSuspendProcess
SSDT 907595B0 ZwSuspendThread
SSDT 90760380 ZwTerminateProcess
SSDT 8F7F2948 ZwTerminateThread
SSDT 8F7DC970 ZwUnmapViewOfSection
SSDT 9076ACA0 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!KeSetTimerEx + 350 81ED5974 8 Bytes [38, 09, 79, 90, B0, 46, 75, ...] {CMP [ECX], CL; JNS 0xffffffffffffff94; MOV AL, 0x46; JNZ 0xffffffffffffff98}
.text ntkrnlpa.exe!KeSetTimerEx + 364 81ED5988 4 Bytes [00, A5, 75, 90]
.text ntkrnlpa.exe!KeSetTimerEx + 370 81ED5994 4 Bytes [F0, 24, 75, 8F]
.text ntkrnlpa.exe!KeSetTimerEx + 428 81ED5A4C 4 Bytes [A8, 30, 79, 90] {TEST AL, 0x30; JNS 0xffffffffffffff94}
.text ntkrnlpa.exe!KeSetTimerEx + 454 81ED5A78 4 Bytes [90, A5, 75, 90] {NOP ; MOVSD ; JNZ 0xffffffffffffff94}
.text ...
.text C:\Windows\system32\DRIVERS\tos_sps32.sys section is writeable [0x8A14D480, 0x3C939, 0xE8000020]
.dsrt C:\Windows\system32\DRIVERS\tos_sps32.sys unknown last section [0x8A18E900, 0x3CA, 0x48000040]
---- User code sections - GMER 1.0.15 ----
? C:\Windows\system32\services.exe[736] C:\Windows\system32\smss.exe image checksum mismatch; time/date stamp mismatch; unknown module: mswsock.dllunknown module: MSWSOCK.dll
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug@StoreLocation C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Report17364d68
---- Files - GMER 1.0.15 ----
File C:\Windows\System32\config\systemprofile\AppData\Local\CrashDumps\svchost.exe.5900.dmp 0 bytes
---- EOF - GMER 1.0.15 ----


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top












